Microsoft is providing notification of the discovery and remediation of a vulnerability affecting Apple Safari version 5.05 and earlier. Microsoft discovered and disclosed the vulnerability under coordinated vulnerability disclosure to the affected vendor, Apple Inc. Apple Inc. has remediated the vulnerability in Safari.
A vulnerability exists in the way Safari handles certain content types. An attacker could exploit this vulnerability to cause Safari to execute script content and disclose potentially sensitive information. An attacker who successfully exploited this vulnerability would gain sensitive information that could be used in further attacks.
Microsoft Vulnerability Research reported this issue to and coordinated with Apple to ensure remediation of this issue. The vulnerability has been assigned the entry, CVE-2010-1420, in the Common Vulnerabilities and Exposures list. For more information, including information about updates from Apple, see Apple Safari Security Alerts.